Hacking electronic shelf labels: Security research with an impact on your grocery shopping. ๐จ๐ปโ๐ป๐ ๏ธ๐ท๏ธ๐๐ธ
Security researchers Jakob Biell, Marius Karstedt, and Konrad Wissel present their research on cybersecurity and potential vulnerabilities in electronic shelf labels, which are used in almost all large stores in the EU.
The authors review electronic shelf-label systems from two major vendors used by top brands in the EU: Picksmart and ZhSunyco. In both systems, the authors find multiple vulnerabilities in local clients, management protocols, credentials, and cloud backends.
In the end, the authors test their findings in a local store, but it is only a partial success: yes, an attacker can change the prices displayed on the shelf labels, but at checkout, the price will still be correct. :)
A very smart and unusual way of choosing a target, with lots of new and interesting details about a product many people use every day and some very cool findings. Strongly recommended reading!
More details:
Priceless: Hacking Electronic Shelf Labels [PDF]: https://troopers.de/downloads/troopers26/TR26_Priceless_DAARST.pdf


